When you type moonactive.pubnubapi.com into your browser, you get a 404 error — the site doesn't exist as a public website. That immediately changes the kind of trust question you're asking. This domain looks like it could be a subdomain for an API or internal service, possibly tied to PubNub's infrastructure. Legitimate backend endpoints often have limited public presence, but they usually belong to a known company with clear documentation. Here, there's nothing visible: no about page, no contact, no social media, no archive history. The domain's owner is completely hidden from WHOIS records.
On the plus side, the connection is encrypted with a valid certificate from Amazon, and no blacklists or Google threats are attached to the domain. That doesn't mean the service behind it is trustworthy — it just means the domain itself hasn't been used for abuse yet. If you're a developer wondering whether to integrate this endpoint into your project, the lack of transparency is a real red flag. Without knowing who runs it or seeing any documentation, you'd be connecting to a black box. The safest move is to treat this domain as unverified until you can trace it back to a known organization or see it used in a legitimate public context.